Last updated: 2026-09-11 · Next review: 2026-12-11 · Scope: EU/EEA · Regulation (EU) 2016/679 Articles 26 and 28 (processor contracts and joint-controller arrangements), read with the EDPB Guidelines 07/2020 role test
Do I need a data processing agreement (DPA)?
A DPA is required when one party processes personal data on behalf of, and on the documented instructions of, the other: the Article 28(3) contract. It is not required between two independent controllers, and joint controllers need a Article 26 arrangement, which is a different instrument. Which one applies turns on the actual roles of the parties, not on what the contract is called. This page walks that screen. It is not legal advice and not a binding determination.
The short version
First confirm personal data is involved at all. Then determine the roles functionally, the way EDPB Guidelines 07/2020 read them: who determines the purposes and means. One party processing on the other's behalf means an Article 28(3) contract (a DPA) before processing starts, with an equivalent contract down any sub-processor chain (Article 28(4)). Jointly determining purposes and means means an Article 26 transparent arrangement, not a DPA. Each party processing for its own purposes means no Article 28 contract at all. The contract's label never settles the role (Article 28(10)), and transfers outside the EU/EEA need their own Chapter V mechanism on top of whatever the relationship requires.
One question, three instruments
“Do we need a DPA?” collapses three different instruments into one word. The GDPR uses different tools for different relationships, and picking the wrong one is worse than picking none: it documents a relationship that does not exist and leaves the real duties unassigned.
- A DPA is the Article 28(3) contract for a controller engaging a processor, with the Article 28(4) equivalent contract down any sub-processor chain.
- An Article 26 arrangement is the transparent allocation of responsibilities for joint controllers, whose essence must be made available to data subjects.
- No Article 28 instrument applies between independent controllers, though a data-sharing arrangement may still be prudent.
This guide uses provision identifiers, short statutory terms, and original plain-English summaries; it does not reproduce full provisions. It is educational content, not legal advice and not a binding determination. Whether a party is a controller, a processor, or a joint controller is a functional judgement for your organisation and its DPO or counsel.
The relationship map at a glance
Each row is a distinct relationship between the parties; identify the one that matches the actual arrangement, not the contract title. The free checker encodes this EU-level split and returns one of four verdicts with the reasons.
| The relationship | The instrument | The key condition |
|---|---|---|
| One party processes personal data on behalf of, and on the documented instructions of, the other | Article 28(3) DPA (before processing starts) | The controller-to-vendor case: SaaS tools, payroll, hosting, email delivery, support desks. Article 28(1) also requires sufficient guarantees from the processor. The instrument can be a contract or another legal act under Union or Member State law; sub-processors need written authorisation and an equivalent contract down the chain (Articles 28(2) and 28(4)). |
| The parties jointly determine the purposes and means | Article 26 transparent arrangement (not a DPA) | Allocates respective responsibilities, in particular toward data subjects; its essence must be made available (Article 26(2)), and data subjects keep their rights against each controller regardless of the allocation (Article 26(3)). Where Union or Member State law already determines the responsibilities, the arrangement is only needed in so far as it does not. Fashion ID: joint controllership is per processing operation. |
| Each party independently determines its own purposes | No Article 28 contract | Separate controllers. A data-sharing arrangement may be prudent but is not a DPA, and naming it a DPA does not create processor duties. Re-check when one side starts processing on the other's behalf. |
| No personal data in the arrangement | Article 28 does not engage | Check the edge cases first: logs, IP addresses, device identifiers, and support attachments routinely carry personal data even when the service is described as technical infrastructure. |
| The role split is not yet clear | Determine the roles, then re-run the screen | The test is functional (EDPB Guidelines 07/2020). Look at who decides purposes and means, who can change the processing, and who negotiated the data uses. Record the analysis; a contract label does not settle it (Article 28(10)). |
Version and jurisdiction stamp: original plain-English summaries of Articles 26 and 28 of Regulation (EU) 2016/679 (GDPR), read with the EDPB Guidelines 07/2020 on the concepts of controller and processor (version 2.1, adopted 7 July 2021, minor corrections 20 September 2022) and CJEU Fashion ID (C-40/17, 29 July 2019). Provision identifiers, short statutory terms, and original plain-English summaries; not full provisions. Checked 2026-09-11. Next review 2026-12-11.
How to decide, step by step
- 1
Check whether personal data is involved at all
“Do I need a DPA?” is not the first question. The first question is whether the arrangement involves personal data at all, in the sense of Article 4(1): information relating to an identified or identifiable living person. Article 28 governs processing carried out on behalf of a controller; where no personal data is processed, that machinery does not engage and no DPA is required on that basis. Be careful with the edge cases before you conclude the rule is off: usage logs, IP addresses, device identifiers, and support attachments routinely carry personal data even when the service is described as infrastructure. If you cannot say what data flows through the arrangement, map it first, then continue.
- 2
Determine the roles functionally, not by what the contract says
The decisive question is who determines the purposes and means of the processing. EDPB Guidelines 07/2020 (adopted 7 July 2021, version 2.1 with minor corrections, 20 September 2022) apply a functional, fact-based test: a controller decides why and how personal data is processed; a processor acts on a controller's behalf and follows its documented instructions; joint controllers jointly determine the purposes and means. The label a contract uses does not settle the role: under Article 28(10), a party that processes data for its own purposes despite being labelled a processor is a controller for that processing. The Court of Justice applied the functional approach in Fashion ID (Case C-40/17, judgment of 29 July 2019), a case decided under the predecessor 1995 Directive and used by the EDPB guidelines: in the circumstances of that case, the operator of a website embedding a social plug-in was held jointly responsible, with the platform, for the collection and transmission stages, while later processing the operator did not determine stayed with the platform. Practical tells: who decided the data uses in the deal, who sets retention periods and recipient categories, and who can change the processing without asking the other party.
- 3
Jointly determine purposes and means: Article 26, not a DPA
If the parties jointly determine the purposes and means, they are joint controllers, and the required instrument is the transparent arrangement of Article 26, not an Article 28 DPA. The arrangement must set out their respective responsibilities for compliance, in particular toward data subjects: who answers which rights requests, who provides the Article 13/14 information, and who handles the Article 15 to 21 rights. Its essence must be made available to the data subjects (Article 26(2)), and the allocation does not bind data subjects: irrespective of the terms of the arrangement, they can exercise their rights against each of the controllers (Article 26(3)). A DPA between joint controllers is the wrong instrument: it implies one party acts on the other's behalf, which is not the relationship, and it does not deliver the transparency the article asks for. Two qualifications keep this step honest. Union or Member State law may already determine the respective responsibilities, in which case the arrangement is needed only in so far as it does not (Article 26(1)). And joint controllership is assessed per processing operation: Fashion ID found joint controllership for the collection and transmission stages, not for everything the platform later does. If one of the parties later starts acting on the other's instructions only, the instrument has to change, not just the wording.
- 4
One party processes on the other's behalf: the Article 28(3) DPA
If the relationship is controller and processor, meaning one party processes personal data on behalf of, and on the documented instructions of, the other, then Article 28(3) requires that processing to be governed by a contract or other legal act under Union or Member State law: for a commercial vendor relationship, the data processing agreement, in writing, including electronic form (Article 28(9)). Article 28(1) adds the controller-side duty to use only processors that provide sufficient guarantees of GDPR-compliant processing, which is why vendor due diligence and the DPA are two halves of one obligation, not alternatives. Put the contract in place before the processing starts. What the contract must cover is not open-ended: the article sets out the processing's subject-matter, duration, nature and purposes, the types of personal data and categories of data subjects, and the controller's obligations and rights, followed by the mandatory processor duties summarised below. Two of those duties carry their own precision. The instructions-only duty yields only where Union or Member State law the processor is subject to requires the processing, and that requirement must be notified to the controller before processing unless the law prohibits notification on important public-interest grounds. And the warning duty is not limited to GDPR infringements: the processor must inform the controller immediately if it believes an instruction breaches the GDPR or other Union or Member State data-protection law. A processor is also directly bound by parts of Article 28 and the Article 32 security duties regardless of the contract, so a DPA is not paperwork that only protects the controller. If the “processor” also determines its own purposes for some processing, that operation needs its own role assessment and the relabeling rule of Article 28(10) applies to it; the genuinely instructed processing still needs its DPA. Where the relationship looks partly one way and partly the other, split the operations and assess each.
- 5
Each party its own purposes: no Article 28 contract
If each party independently determines its own purposes, they are separate controllers, and Article 28 does not apply between them: no controller-processor relationship arises, so no DPA is required on that basis. A data-sharing arrangement covering each party's lawful basis, retention, security, and incident cooperation may still be prudent, but it is a different artefact with a different job; renaming it a DPA does not bring Article 28 into play, and having one does not create processor duties that do not exist. Keep the assessment and its reasoning with your records, and re-check when the arrangement changes: the moment one party starts processing on the other's behalf (support, hosting, analytics, delivery), the relationship moves into Article 28 territory and the screen has to run again.
- 6
Handle sub-processors, transfers, then record and re-check
Two refinements sit on top of whatever the relationship requires, and neither changes the relationship branch itself. First, sub-processors: a processor may engage a sub-processor only with the controller's prior specific or general writtenauthorisation (Article 28(2)). Under general authorisation, the processor must inform the controller of any intended addition or replacement of processors, giving the controller the opportunity to object. The processor must impose the same data-protection obligations on each sub-processor by contract (Article 28(4)) and remains fully liable to the controller for the sub-processor's performance. In practice that means an equivalent contract down the chain, not just a list in the appendix. Second, international transfers: if personal data leaves the EU/EEA, Chapter V needs its own mechanism, for example an adequacy decision or standard contractual clauses with a transfer impact assessment where safeguards are needed. The DPA and the transfer mechanism are separate layers: Article 28 compliance alone does not establish transfer compliance. Record the role analysis with your records, and re-run the screen when the arrangement changes, because roles drift: a hosting vendor becomes a processor the moment it stores personal data for you, and a partner may become a joint controller where a shared campaign jointly determines the relevant personal-data processing. Choosing merely technical implementation details, on the other hand, does not by itself make a processor a joint controller.
Article 28 DPA vs Article 26 arrangement, in one place
This is the confusion behind most “do we need a DPA?” questions, so it is worth isolating. Two instruments, two different relationships, two different sets of required content.
Article 28(3): the DPA
For a controller engaging a processor: one party processes on behalf of, and on the documented instructions of, the other. The instrument is a contract or another legal act under Union or Member State law, in writing, including electronic form (Article 28(9)). The contract must identify what processing is covered, how long it lasts, why and how it is performed, the types of personal data and categories of data subjects, and the controller's obligations and rights, and must stipulate the Article 28(3) processor duties: instructions only (including transfer instructions, unless Union or Member State law the processor is subject to requires the processing, which must be notified before processing unless the law prohibits notification on important public-interest grounds; with an immediate warning if the processor believes an instruction breaches the GDPR or other Union or Member State data-protection law), confidentiality for authorised staff, Article 32 security, sub-processor controls, assistance with data subject rights and with the Articles 32 to 36 compliance duties, deletion or return at the controller's choice with copies deleted unless Union or Member State law requires storage, and information and audit cooperation including inspections. The processor stays directly on the hook for its own duties under Article 28 and Article 32 regardless of the contract text.
Article 26: the joint-controller arrangement
For two or more controllers jointly determining purposes and means: a transparent arrangement setting out their respective responsibilities for compliance, in particular the transparency duties toward data subjects and the handling of data subject rights (Articles 15 to 21), with its essence made available to the data subjects (Article 26(2)). Irrespective of the arrangement's terms, data subjects can exercise their rights against each of the controllers (Article 26(3)), so the allocation does not bind them. Where Union or Member State law already determines the respective responsibilities, the arrangement is only needed in so far as it does not (Article 26(1)). It answers “who does what,” not “who acts for whom.”
If you are unsure which relationship you are in, that is itself the finding: settle who determines purposes and means, per processing operation, before you pick the instrument. EDPB Guidelines 07/2020 and the Fashion ID judgment show the test applied to embedded plug-ins, platforms, and service chains.
Run the same screen as a free interactive check
The free DPA necessity checker asks six questions (personal data involved, the relationship between the parties, your side, whether the processor acts on instructions only, sub-processors, and international transfers), then returns a structured assessment with the reasons: dpa-required (with the Article 28(3) mandatory content), art26-arrangement, consider, or not-required. Use this guide for the method; use the checker to run it. Both are starting points, not legal advice: the roles are a functional judgement call under Article 4 and the EDPB Guidelines 07/2020, and a contract label does not settle them (Article 28(10)). The checker runs in your browser and stores nothing.
Six mistakes that produce the wrong instrument
Assuming every vendor relationship needs a DPA
The instrument follows the relationship. Two independent controllers do not need an Article 28 contract between them, and joint controllers need an Article 26 arrangement instead. Buying a DPA template and sending it to every counterparty does not fix a misassigned role; it documents the wrong one.
Letting the contract label settle the roles
Calling a party a processor does not make it one. Under Article 28(10), a processor that determines its own purposes and means for a processing operation is a controller for that operation, whatever the contract says. EDPB Guidelines 07/2020 read the roles functionally: who decided the purposes, who can change the processing, who bears the instructions. Genuinely instructed processing keeps its DPA; own-purpose processing needs its own assessment.
Signing a DPA between joint controllers
Joint controllers need the Article 26 arrangement, with responsibilities allocated transparently and its essence made available to data subjects, who keep their rights against each controller (Article 26(3)). An Article 28 contract implies one party merely follows the other's instructions, and it does not deliver the transparency Article 26 asks for. The wrong instrument leaves real duties unassigned.
Treating a signed DPA as a transfer mechanism
Chapter V is its own question. A transfer of personal data outside the EU/EEA needs an adequacy decision or, for example, standard contractual clauses with a transfer impact assessment, regardless of how good the Article 28 contract is. Where the standard clauses apply, the right module can carry both the Article 28 terms and the transfer mechanism in one set; what it can never do is let Article 28 compliance stand in for transfer compliance. Vendors that answer a transfer question with 'we have a DPA' have answered a different question.
Forgetting the chain
Article 28(2) and 28(4) apply at every level: the processor needs the controller's written authorisation for each sub-processor (specific, or general with notice of additions and an opportunity to object), must impose the same obligations by contract, and stays fully liable for the sub-processor's performance. A DPA that stops at the first level leaves the rest of the chain undocumented.
Treating the role analysis as a one-time exercise
Roles drift. A hosting vendor becomes a processor the day it stores personal data for you; a partner may become a joint controller where a shared campaign jointly determines the relevant personal-data processing; a processor becomes a controller if it starts using your data for its own purposes. Re-run the screen when the arrangement changes, and keep the assessment with your records.
Where this page sits in the GDPR cluster
| Surface | Job | Format |
|---|---|---|
| This guide | Explain the Article 28 vs Article 26 instrument screen so a person (or an AI answer) can follow which contract an arrangement needs | Long-form guide |
| DPA necessity checker | Run the same Article 28/26/4 role screen as a six-question questionnaire | Free tool |
| Do I need a DPIA? | The Article 35 high-risk screen, a different GDPR question from vendor contracts | Long-form guide |
| Do I need cookie consent? | The ePrivacy Article 5(3) screen, a different GDPR question from both | Long-form guide |
| Free compliance tools hub | The rest of the GDPR toolkit (ROPA, EU representative, cookie checker) and the other free checkers | Tools index |
Frequently asked questions
Do I need a data processing agreement?
You need a DPA (the Article 28(3) contract) when one party processes personal data on behalf of, and on the documented instructions of, the other: the classic controller-to-vendor relationship. You do not need a DPA between two independent controllers each processing for its own purposes, and joint controllers need an Article 26 transparent arrangement instead, which is a different instrument. The answer turns on the actual roles, not on what the contract is called: a party labelled a processor that determines its own purposes is a controller for that processing (Article 28(10)). Where sub-processors are involved, an equivalent contract is required down the chain (Article 28(4)).
What is a DPA under GDPR?
A data processing agreement is the written contract that Article 28(3) of the GDPR requires before a processor processes personal data on a controller's behalf (Article 28(9) allows writing in electronic form). It must set out the processing's subject-matter, duration, nature and purposes, the types of personal data and categories of data subjects, and the controller's obligations and rights, and must stipulate the processor duties: process only on documented instructions (including for transfers, unless Union or Member State law the processor is subject to requires the processing, which must be notified in advance unless the law prohibits notification on important public-interest grounds), confidentiality for authorised staff, Article 32 security measures, sub-processor conditions, assistance with data subject rights and with the controller's Articles 32 to 36 compliance, deletion or return at the controller's choice with copies deleted unless Union or Member State law requires storage, and information and audit rights including the duty to warn the controller immediately if an instruction is believed to breach the GDPR or other Union or Member State data-protection law. The parties may call it a data processing addendum; the name does not matter, the Article 28(3) content does.
Do two independent controllers need a DPA between them?
No. If each party determines its own purposes and means for the data it processes, there is no controller-processor relationship and Article 28 does not require a DPA between them. A data-sharing agreement covering each party's lawful basis, retention, security, and incident cooperation may still be prudent, but it is not a DPA and calling it one does not change the analysis. Re-check when the arrangement changes: if one party starts processing on the other's behalf, the relationship moves into Article 28.
What arrangement do joint controllers need?
An Article 26 arrangement, not a DPA. Where two or more controllers jointly determine the purposes and means of processing, they must set out their respective responsibilities for compliance in a transparent arrangement, in particular the transparency duties toward data subjects, and make its essence available to them (Article 26(2)). Irrespective of the arrangement's terms, data subjects can exercise their rights against each of the controllers (Article 26(3)). Union or Member State law may already determine the respective responsibilities, in which case the arrangement is only needed in so far as it does not. Signing an Article 28 DPA between joint controllers is the wrong instrument: it implies one party acts on the other's behalf and does not deliver the transparency Article 26 requires. Joint controllership is also per processing operation: Fashion ID (Case C-40/17) found joint controllership for the collection and transmission stages of embedded plug-ins, not for everything the platform later does.
Do sub-processors need their own contract?
Yes, in the chain that Article 28 sets up. A processor may engage a sub-processor only with the controller's prior specific or general written authorisation (Article 28(2)); under general authorisation the processor must inform the controller of any intended addition or replacement, giving the controller the opportunity to object. The processor must impose the same data-protection obligations on the sub-processor by contract (Article 28(4)) and stays fully liable to the controller for the sub-processor's performance. Practically, that means an Article 28(4) equivalent contract at each level of the chain, not just between the top two parties.
Does a DPA cover international data transfers?
No. A DPA governs the controller-processor relationship; Article 28 compliance alone does not establish transfer compliance. A transfer of personal data outside the EU/EEA needs its own mechanism under Chapter V of the GDPR: an adequacy decision where one exists, or, for example, standard contractual clauses plus a transfer impact assessment where safeguards are needed. The Chapter V route depends on the facts of the transfer, and where the standard clauses apply, the applicable module can carry both the Article 28 contract terms and the transfer mechanism in one set of clauses. In practice you will often sign both layers, but they answer different questions: the free checker carries this as a separate flag rather than a different verdict.
How is this different from the free DPA necessity checker?
This page is the long-form method: whether personal data is involved, how to determine the roles functionally, which instrument each relationship requires, what the Article 28(3) contract must cover, and how sub-processors and transfers fit in, with the primary sources. The free DPA necessity checker at /resources/gdpr-dpa-necessity-checker runs the same screen as a six-question questionnaire and returns a structured assessment (dpa-required, art26-arrangement, consider, or not-required) with the reasons. Use the guide to understand the test; use the checker to run it. Neither is legal advice or a binding determination: whether a party is controller, processor, or joint controller is a functional judgement call under Article 4 and the EDPB Guidelines 07/2020, and the label a contract uses does not settle it (Article 28(10)).
Primary sources
- Regulation (EU) 2016/679 (GDPR), Articles 26 (processing under the joint control of two or more controllers: the transparent arrangement, the law exception in 26(1), the essence made available in 26(2), and rights against each controller in 26(3)), 28 (processor: the sufficient-guarantees duty of 28(1), written sub-processor authorisation in 28(2), the mandatory contract content of 28(3), the equivalent-obligations contract in 28(4), and the electronic-form rule in 28(9)), and 4(7)/(8) (controller and processor definitions) (EUR-Lex). eur-lex.europa.eu (checked 2026-09-11).
- EDPB Guidelines 07/2020 on the concepts of controller and processor in the GDPR, version 2.1 (adopted 7 July 2021; version 2.1 with minor corrections, 20 September 2022): the functional, fact-based test for the roles, the joint-controllership analysis, and the case-law discussion including Wirtschaftsakademie and Fashion ID. www.edpb.europa.eu (checked 2026-09-11).
- CJEU, Fashion ID (Case C-40/17), judgment of 29 July 2019 (decided under the predecessor 1995 Directive and used by EDPB Guidelines 07/2020: in the circumstances of that case, the operator of a website embedding a social plug-in was jointly responsible with the platform for the collection and transmission stages, not for later processing it did not determine). eur-lex.europa.eu (checked 2026-09-11).
Written and maintained by the ISMS Copilot team. Last reviewed 2026-09-11. Next review 2026-12-11.
This page summarises, in original wording, Articles 26 and 28 of Regulation (EU) 2016/679 (GDPR) and applies the functional controller/processor test set out in EDPB Guidelines 07/2020 (version 2.1, adopted 7 July 2021, minor corrections 20 September 2022), with the joint-controllership case law discussed there. It is educational content, not legal advice and not a binding determination of any party's role or any arrangement's instrument. Confirm against the current Official Journal text, EDPB guidance, your DPO or counsel, and your supervisory authority.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
